Data Haven

Keep it all.
Find it fast.

Data Haven is the searchable retention layer of the Realm Platform. All your log data is kept automatically. When an investigation needs older data, you search your full history and resupply the exact events you need.

Data Haven / Search src_ip = 203.0.113.44
Observable matched src_ip 203.0.113.44 · 14 months history 0.4s
Events found Exact records, not a coarse range 1,284
Resupplied Sent to Sentinel · no rebuild Done
Search the full history in place. Resupply only what the investigation needs.
The problem

Stored is not the same as usable

Because the SIEM charges by ingest, teams push older telemetry into cheaper storage. It solves the cost issue and creates a new problem: when you need that data back, it's difficult to get it.

1

Restore a wide range

You can't see inside stored data to target the events you want, so you pull back a coarse, oversized range.

2

Pay and wait

You pay to bring back far more than you need, then wait for it to land while the incident runs.

3

Dig by hand

You search the raw result manually for the few records that count. And some data may have been filtered out and never kept at all.

As volumes climb year over year, the gap between what is stored and what is usable only widens.

What Data Haven is

An immutable raw copy of your security data, with OCSF-normalized observables on every event. Search your full history directly, and resupply the exact events to any destination.

What you get

Retention you trust. Search that's ready.

Complete retention

Nothing dropped, nothing to configure

A complete raw copy of all your security data, retained automatically with OCSF observables attached. Your full history stays complete and audit-ready in one place.

  • Zero-configuration, every source routed automatically
  • Complete capture, not a cost-filtered subset
  • Retention set with checkboxes, no engineering
Direct Search & Targeted Resupply

Search in place, resupply exact events

Search your entire history directly, using the observables your SOC already works in. No rebuild before you query. Find the exact events and resupply only those, anywhere.

  • Full-history search, no rebuild first
  • Observable-based, pinpoint exact events
  • Resupply to any destination, not just the SIEM
Control & ownership

Your data, open format, no limits

Your data stays yours in an open, portable format. Keep as much as you want, as long as you want, with no storage cap. Send it anywhere. Never run infrastructure to do it.

  • Open, portable format, not locked to any tool
  • Priced on ingest, not on how much you search
  • Fully managed, no storage cap
How it works

Store. Search. Resupply.

1
Store

Everything, automatically

Every connected source routes to Data Haven and keeps a complete, immutable raw copy, in an encrypted open format alongside its OCSF fields, observables, and enrichments.

2
Search

Your full history, in place

Query your entire OCSF-normalized history by time range, source, and observable. A graphical query builder means no new query language to learn.

3
Resupply

Only what you need

Send only the events you found to the destination you choose. No coarse restore, no manual dig, no wait.

Competitive frame

Keeping your data isn't the same as using it

An archive tier and a data lake can both store your history. In both, the data is frozen until you rebuild it, or expensive to search.

Approach Search your history Cost to use it
Data Haven Complete capture, searchable in place with no rebuild. Priced on ingest. Search and resupply as much as you need.
SIEM archive tier Slow to restore. Frozen until you thaw and rebuild it. Pay compute to retrieve and query.
General-purpose data lake Build schemas and transforms before anything is queryable. The engineering and upkeep to run it.
Metered stores Searchable, but you pay per scan every query. Charges stack up mid-investigation.
Straight answers

The questions a Head of SecOps actually asks

What is Realm Data Haven?

Data Haven is the searchable retention layer of the Realm Platform. It keeps an immutable raw copy of your security data with OCSF-normalized observables attached, and lets you search your full history directly, then resupply the exact events you need to any destination.

It is purpose-built for security and fully managed , so there is no infrastructure to stand up or run.

How is a searchable retention layer different from a SIEM?

A SIEM runs real-time detection, correlation, and alerting on recent data. A searchable retention layer holds your full security history affordably and lets you search and retrieve older events on demand.

Data Haven is a retention layer, not a SIEM : it feeds your SIEM and detection stack, it does not replace them. Detection and alerting stay in the SIEM.

How is Data Haven different from a security data lake?

A security data lake is a general-purpose toolkit you build on and operate, which means schemas, transforms, and the engineering to run it.

Data Haven is purpose-built for security and fully managed: data lands normalized and immediately searchable on observables, with nothing to set up or maintain. You get the retention and the search without the build.

How do I search and retrieve archived security logs without rebuilding them?

Use a retention layer that keeps data in a searchable format so you can query it in place, instead of a cold archive that freezes logs and forces a rebuild first.

With Data Haven, logs are captured automatically and stay searchable: you query your history on OCSF-normalized observables and retrieve only the exact events you need, with no rebuild step . This turns log retrieval from a slow batch process into a direct search.

How is Data Haven priced?

Data Haven is priced on what you ingest, not on how much you query or retrieve. You can search and pull data as much as an investigation needs without per-query or per-access charges stacking up.

This is the difference from metered stores like Sumo Logic, which charge per scan on every query.

Is data in Data Haven encrypted and tamper-proof?

Yes. Data Haven encrypts data at rest and in transit, and stores it as an immutable copy, so your raw logs are preserved and attestable. Your retained history stays intact whether or not you resupply from it.

Searches and resupplies are logged, so you have a record of who accessed what and when. Role-based access lets you scope data sources to specific user groups.

Pick one source.
We'll prove it on your data in days.

The 7-Day Data Assessment. You pick a source, usually firewall logs. We do everything else, and deliver your reduction, detection integrity, and ROI on your own data in a week.

Start a 7-Day Data Assessment